> Markdown version of [/jobs/ext/1410131-issm-ato-program-lead-ecs-mns](https://www.wearedevelopers.com/jobs/ext/1410131-issm-ato-program-lead-ecs-mns). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ISSM - ATO Program Lead (ECS/MNS) - **Company:** Tlingit Haida Tribal Business Corporation - **Location:** Atlanta, GA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Word, Microsoft Excel, Microsoft Outlook, Cyber Security, Information Systems, Information Security Management, Microsoft Office, Software Vulnerability Management, SARS Software Products, Information Technology - **Published:** July 23, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=0c660941fb78f4b5 ## About the Role * 10+ years supporting cybersecurity, information assurance, or federal information systems. * 5+ years serving as an ISSM, Senior ISSO, Cybersecurity Lead, or equivalent role supporting Authority to Operate (ATO) efforts. * Experience supporting mission-critical communications, emergency communications, or critical infrastructure systems. * Demonstrated experience leading RMF packages through the ATO process for DoD or other federal agencies. * Experience with NIST Risk Management Framework (RMF), NIST SP 800-37, NIST SP 800-53, DISA STIGs, Security Technical Implementation Guides, and continuous monitoring. * Experience using Enterprise Mission Assurance Support Service (eMASS) or comparable authorization management systems. * Strong understanding of cybersecurity governance, vulnerability management, system hardening, and risk management. * Experience coordinating with Government Authorizing Officials (AO), Security Control Assessors (SCA), ISSOs, ISSEs, and Program Managers. * Excellent written and verbal communication skills with the ability to communicate cybersecurity risks to both technical and executive stakeholders. * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related field; equivalent experience considered. * Must be able to obtain and maintain required Government security or facility access credentials. * Proficiency in Microsoft Office Suite (Word, Excel, Outlook); experience with work order systems such as Maximo preferred. * Must be able to maintain the ability to access the government worksite. * Must possess and maintain a valid state driver's license and a safe driving record, in accordance with company policy, to operate vehicles or equipment as required for the position., * Experience with Emergency Communication Systems (ECS), Mass Notification Systems (MNS), fire alarm systems, building automation systems, or critical infrastructure modernization. * Knowledge of NFPA 72, voice evacuation systems, Giant Voice, telecommunications, or enterprise network infrastructure * Previous experience leading multiple ATOs or enterprise cybersecurity programs. ## Description The ATO Program Lead (Information System Security Manager) provides cybersecurity leadership for the successful authorization, accreditation, and lifecycle management of systems supporting the Emergency Communication System (ECS) and Mass Notification System (MNS) modernization program. The role serves as the primary cybersecurity advisor responsible for Risk Management Framework (RMF) execution, Authority to Operate (ATO) activities, continuous monitoring, and cybersecurity compliance across the program., * Lead all Authority to Operate (ATO) activities throughout the system lifecycle. * Serve as the Information System Security Manager (ISSM) supporting cybersecurity governance for the program. * Manage implementation of the NIST Risk Management Framework (RMF) and applicable DoD cybersecurity requirements. * Coordinate with Government Authorizing Officials (AO), ISSOs, ISSEs, cybersecurity assessors, and program leadership throughout the authorization process. * Oversee development, review, and maintenance of RMF documentation including System Security Plans (SSPs), POA&Ms, Security Assessment Reports (SARs), Continuous Monitoring Plans, and supporting authorization artifacts. * Ensure compliance with DoD cybersecurity policies, NIST 800-series publications, DISA STIGs, and applicable federal security requirements. * Lead vulnerability management activities including remediation planning, risk acceptance, and security compliance reporting. * Support cybersecurity architecture reviews to ensure security requirements are incorporated into system design and implementation. * Advise project leadership on cybersecurity risks, mitigation strategies, and authorization status. * Coordinate security testing, assessment activities, and continuous monitoring efforts. * Support accreditation of interconnected systems and enterprise network integrations. * Performs other duties as assigned., * Primarily office-based with periodic travel to customer and project sites. * Must be able to conduct field visits, navigate active work environments, and work extended hours as required to support mission needs. * Must be able to work on-call, alternate, and extended shift schedules when necessary to meet the mission requirements, including weekends and holidays. Why Us? At Tlingit Haida Tribal Business Corporation (THTBC), our work goes beyond delivering exceptional services-we are driven by a mission to create meaningful impact. When you join our team, you become part of an organization that values purpose, performance, and people. We offer the opportunity to work in dynamic, fast-paced environments where your contributions directly impact mission success. Our teams are built on collaboration, accountability, and a commitment to excellence, ensuring you are supported while being challenged to grow. Join us and be part of a team where your work matters. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [In-depth .NET Azure Functions: Isolated mode, performance and durable AI agents](https://www.wearedevelopers.com/videos/100207-in-depth-net-azure-functions-isolated-mode-performance-and-durable-ai-agents) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Developing the Rich Text Editor for DeepL.com](https://www.wearedevelopers.com/videos/1172-developing-the-rich-text-editor-for-deepl-com) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions)